morpheus

Aliases: HellCat

First seen
2020-03-15 00:00:00
Malware type
rat, trojan
Family
Malware family
Last IoC activity
2026-06-04 21:31:13
Profile updated
2026-07-07 13:55:03

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:us country_code:de country_code:ru

Context

Morpheus, also known as HellCat, is a remote access trojan used by threat actors to conduct cyber-espionage activities. It targets sensitive sectors such as financial services and government entities, often leading to the unauthorized access and theft of sensitive information.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Morpheus_Auto (yara-rule)

Reports & references

  • ransomlook.io — Morpheus (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Morpheus (report)
  • zscaler.com — Technical Analysis Transferloader (report)
  • sentinelone.com — Hellcat And Morpheus Two Brands One Payload As Ransomware Affiliates Drop Identical Code (report)
  • picussecurity.com — Hellcat Ransomware (report)

External references